Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
bypass-url-parser — 生のcurlリクエストを使用して、40X保護ページに対して数百のURLバイパス手法をテストし、マルチモードスキャン、ヘッダースプーフィング、およびアクセス制御評価のためのJSON/HTML結果エクスポートを備えています。 | Kitploit
ツール/GitHubGitHub/laluka/bypass-url-parser
脆弱性分析情報収集WAFバイパスウェブセキュリティペネトレーションテスト
GitHublaluka/bypass-url-parser

bypass-url-parser

生のcurlリクエストを使用して、40X保護ページに対して数百のURLバイパス手法をテストし、マルチモードスキャン、ヘッダースプーフィング、およびアクセス制御評価のためのJSON/HTML結果エクスポートを備えています。

リポジトリを見る
1.1k122121年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
ウェブサイト
共有

Bypass Url Parser

PyPI - Version PyPI - Python Version PyPI - License pdm-managed

多くの MANY urlバイパスをテストして、40X protected page に到達するツール。

なぜこのコードが単なる汚いcurlラッパーなのか疑問に思うなら、その理由は次のとおりです。

  • ほとんどのpython requestsは、url/path/parameterのエンコード/デコードを行い、私はこれが嫌いです。
  • 生の文字を送信するなら、生の文字を送信したい。
  • 奇妙なパスを送信するなら、奇妙なままであってほしい。正規化されてはならない。

これは、パース、SSL/TLSカプセル化などのライブラリの便利機能すべてを失わずにpythonで実現するのは、驚くほど難しい。
だから、私のように、curl をバックエンドとして 使ってください。問題ありません。

また、このツールはライブラリとしても使用できます。lib_sample_usage.py を参照してください。

インストール

このツールのインストールにはpipxの使用をお勧めします。```bash pipx install bypass-url-parser

or for the latest dev version

pipx install git+https://github.com/laluka/bypass-url-parser

代わりに、`pip`を使用することもできます:```bash
pip install bypass-url-parser

使い方```

Bypass Url Parser, made with love by @TheLaluka A tool that tests MANY url bypasses to reach a 40X protected page.

Usage: bypass-url-parser (-u | -R ) [-m ] [-o ] [-S ] [ (-H

)...] [-r ] [-s ] [--spoofip-replace] [-p ] [--spoofport-replace] [-t ] [-T ] [--request-tls] [--jsonl] [--dump-payloads] [-x <proxy_url>] [-v | -d | -dd]

Program options: -u, --url URL (path is optional) to run bypasses against -R, --request Load HTTP raw request from a file -H, --header

Header(s) to use, format: "Cookie: can_i_haz=fire" -m, --mode Bypass modes. See 'Bypasser.BYPASS_MODES' in code [Default: all] -o, --outdir Output directory for results -x, --proxy <proxy_url> Set a proxy in the format http://proxy_ip:port. -S, --save-level Save results level. From 0 (DISABLE) to 3 (FULL) [Default: 2] -s, --spoofip IP(s) to inject in ip-specific headers -p, --spoofport Port(s) to inject in port-specific headers -r, --retry Retry attempts of failed requests. Set 0 to disable all retry tentatives [Default: 1] -t, --threads Scan with N parallel threads [Default: 1] -T, --timeout Request times out after N seconds [Default: 5]

General options: -h, --help Show help, you are here :) -v, --verbose Verbose output -d, --debug Show more details like curl commands generated by this tool -dd, --debug Print Debug level 2 (with all classes debug_class output) -V, --version Show version info

Misc options: --spoofip-replace Disable list of default internal IPs in 'http_headers_ip' bypass mode --spoofport-replace Disable list of default internal ports in 'http_headers_port' bypass mode --request-tls Force usage of TLS/HTTPS for the request load with the '-R, --request' option --dump-payloads Print all payloads (curls) generated by this tool. --jsonl Print results in JSON lines format (pipe command output)

Examples: bypass-url-parser -u "http://127.0.0.1/juicy_403_endpoint/" -s 8.8.8.8 -d bypass-url-parser -u /path/urls -t 30 -T 5 -H "Cookie: me_iz=admin" -H "User-agent: test" bypass-url-parser -R /path/request_file --request-tls -m "mid_paths, end_paths"

## 期待される結果```bash
bypass-url-parser -u http://127.0.0.1:8000/foo/bar
2022-08-09 14:52:40 lalu-perso bup[361559] WARNING Trying to bypass 'http://127.0.0.1:8000/foo/bar' url (3213 payloads)...
2022-08-09 14:52:40 lalu-perso bup[361559] INFO Doing: 50 / 3213
[...]
2022-08-09 14:52:54 lalu-perso bup[361559] INFO Doing: 3200 / 3213
2022-08-09 14:52:54 lalu-perso bup[361559] INFO Retry (1/3) the '16' failed curl commands with 10 threads and 10s timeout
2022-08-09 14:52:54 lalu-perso bup[361559] INFO Retry (2/3) the '16' failed curl commands with 5 threads and 20s timeout
2022-08-09 14:52:54 lalu-perso bup[361559] INFO Retry (3/3) the '16' failed curl commands with 1 threads and 30s timeout
2022-08-09 14:52:55 lalu-perso bup[361559] INFO
[#####] [bypass_method] [payload] => [status_code] [content_type] [content_length] [lines_count] [word_counts] [title] [server] [redirect_url]
[GROUP (1587)] [original_request] [http://127.0.0.1:8000/foo/bar] => [404] [text/html] [469] [14] [95] [Error response] [SimpleHTTP/0.6 Python/3.8.10] []
[GROUP (10)] [http_methods] [-X CONNECT http://127.0.0.1:8000/foo/bar] => [501] [text/html] [500] [14] [96] [Error response] [SimpleHTTP/0.6 Python/3.8.10] []
[SINGLE] [mid_paths] [http://127.0.0.1:8000/???foo/bar] => [200] [text/html] [913] [26] [27] [Directory listing for /???foo/bar] [SimpleHTTP/0.6 Python/3.8.10] []
[SINGLE] [mid_paths] [http://127.0.0.1:8000//???foo/bar] => [301] [] [] [0] [0] [] [SimpleHTTP/0.6 Python/3.8.10] [/???foo/bar]
[SINGLE] [mid_paths] [http://127.0.0.1:8000/??foo/bar] => [200] [text/html] [911] [26] [27] [Directory listing for /??foo/bar] [SimpleHTTP/0.6 Python/3.8.10] []
[SINGLE] [mid_paths] [http://127.0.0.1:8000//??foo/bar] => [301] [] [] [0] [0] [] [SimpleHTTP/0.6 Python/3.8.10] [/??foo/bar]
[SINGLE] [mid_paths] [http://127.0.0.1:8000/?foo/bar] => [200] [text/html] [909] [26] [27] [Directory listing for /?foo/bar] [SimpleHTTP/0.6 Python/3.8.10] []
[SINGLE] [mid_paths] [http://127.0.0.1:8000//?foo/bar] => [301] [] [] [0] [0] [] [SimpleHTTP/0.6 Python/3.8.10] [/?foo/bar]
[SINGLE] [mid_paths] [http://127.0.0.1:8000///?anythingfoo/bar] => [200] [text/html] [929] [26] [27] [Directory listing for ///?anythingfoo/bar] [SimpleHTTP/0.6 Python/3.8.10] []
[SINGLE] [mid_paths] [http://127.0.0.1:8000////?anythingfoo/bar] => [200] [text/html] [931] [26] [27] [Directory listing for ////?anythingfoo/bar] [SimpleHTTP/0.6 Python/3.8.10] []
[GROUP (2)] [mid_paths] [http://127.0.0.1:8000/#?foo/bar] => [200] [text/html] [893] [26] [27] [Directory listing for /] [SimpleHTTP/0.6 Python/3.8.10] []
[GROUP (2)] [mid_paths] [http://127.0.0.1:8000//#?foo/bar] => [301] [] [] [0] [0] [] [SimpleHTTP/0.6 Python/3.8.10] [/]

セットアップ

LINUX```bash

Deps

sudo apt install -y bat curl virtualenv python3

Tool

virtualenv -p python3 .py3 source .py3/bin/activate PDM_BUILD_SCM_VERSION="$(git describe --abbrev=0)-dev" pip install .

If bup installed globally, use

python src/bypass_url_parser/init.py -u https://thinkloveshare.com/juicy_403_endpoint/

Else this should work

bypass-url-parser -u https://thinkloveshare.com/juicy_403_endpoint/ cat /tmp/tmpRANDOM-bypass-url-parser/triaged-bypass.json | jq -r '.results[].request_curl_cmd' cat /tmp/tmpRANDOM-bypass-url-parser/triaged-bypass.json | jq -r '.results[].response_data'

### DOCKER```bash
docker run --rm -it -v "$PWD:/host" -w /host ghcr.io/laluka/bypass-url-parser:latest bash -il
# Then bup -h, keep the docker open as the output is saved by default in /tmp
# Or specify the output to the current directory, and consult them later! :)

サポートされている引数の詳細

引数の解析

Bypass_url_parser では、いくつかの引数をさまざまな方法で定義できます:

  • -m, --mode、-s, --spoofip、-p, --spoofport 引数は、ファイル名、文字列、カンマ区切りの文字列リスト、またはリスト(Bypasser をライブラリとして使用する場合)にすることができます;
  • -u, --url 引数は、ファイル名、文字列、またはリスト(Bypasser をライブラリとして使用する場合)にすることができます;
  • stdin(- を使用)は、これらすべての引数でサポートされています。

たとえば、複数のターゲットURL(-u, --url)を定義する場合、以下のすべてのコマンドは同じ結果を生成します:```bash bypass-url-parser -u http://thinkloveshare.com/test bypass-url-parser -u /path/urls cat /path/urls | bypass-url-parser -u - echo 'http://thinkloveshare.com/test' | bypass-url-parser -u -

### ターゲット定義

ツールを動作させるにはターゲットを定義する必要があります。2つのオプションがあります:
ツールをダウンロード